Записи PROLiNK
4 опубликованных записей вендора prolink.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-36705Эксплойта нет | In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 containprolink · prc2402m firmware · CWE-78 | Критическая9,8 | — | 2,6 % | 6 авг. 2021 г. |
40В плане | CVE-2021-36706Эксплойта нет | In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contprolink · prc2402m firmware · CWE-78 | Критическая9,8 | — | 2,6 % | 6 авг. 2021 г. |
40В плане | CVE-2021-36707Эксплойта нет | In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff cprolink · prc2402m firmware · CWE-77 | Критическая9,8 | — | 2,6 % | 6 авг. 2021 г. |
30Наблюдать | CVE-2021-36708Эксплойта нет | In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the admprolink · prc2402m firmware · CWE-640 | Высокая7,5 | — | 1,2 % | 6 авг. 2021 г. |
- CVE-2021-3670540В плане
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contain
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %prolink · prc2402m firmware6 авг. 2021 г.
- CVE-2021-3670640В плане
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD cont
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %prolink · prc2402m firmware6 авг. 2021 г.
- CVE-2021-3670740В плане
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff c
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %prolink · prc2402m firmware6 авг. 2021 г.
- CVE-2021-3670830Наблюдать
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the adm
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %prolink · prc2402m firmware6 авг. 2021 г.